Legal

Privacy Policy

Last updated: June 18, 2026  ·  Applies to all RafterCore users worldwide

Your privacy matters. RafterCore is committed to handling your personal information with transparency, care, and respect. This policy explains exactly what we collect, why we collect it, how we use it, and what rights you have.

1. Who We Are

RafterCore is operated by RafterCore LLC, a Phoenix, Arizona-based company providing a SaaS platform for roofing contractors and homeowners. References to "RafterCore," "we," "us," or "our" throughout this policy refer to RafterCore LLC.

For privacy inquiries, contact us at: contact@raftercore.com or 1-833-723-8371.

2. Information We Collect

Information you provide directly:

CategoryExamplesPurpose
Account infoName, business name, email, password, phone, city, stateAccount creation and authentication
Business dataClient records, job details, invoices, photos, estimates, team member infoCore platform functionality
Payment infoBilling email (card numbers handled entirely by Stripe)Subscription billing
CommunicationsSupport messages, booking requests, client communicationsCustomer support and platform features

Information collected automatically:

3. How We Use Your Information

We use your information to:

We do not use your data to serve third-party advertising. We do not sell your data to data brokers.

4. How We Share Your Information

We share your data only in these circumstances:

Service providers (data processors):

ProviderPurposeData Shared
StripePayment processingEmail, subscription details
SupabaseDatabase & authenticationAll account & business data
Anthropic ClaudeAI featuresAddress/property queries, job context
Vapi.aiAI voice callsCustomer phone, name, booking details
VonageSMS messagingPhone numbers, message content
GoogleCalendar integrationBooking details with your consent

Each provider operates under its own privacy policy and our data processing agreements requiring them to protect your data.

Between merchants and customers: When a homeowner books through your customer portal, their contact information is shared with you as the merchant. This is core to the platform's function.

Legal requirements: We may disclose information when required by law, court order, or government authority, or to protect the rights, property, or safety of RafterCore, our users, or the public.

Business transfers: If RafterCore is acquired or merged, your information may be transferred as part of that transaction. We will notify you in advance.

5. Data Storage & Security

Your data is stored in Supabase's cloud infrastructure with the following protections:

While we take security seriously and implement industry-standard protections, no system is completely secure. We cannot guarantee absolute security of your data.

6. Data Retention

7. Your Rights & Choices

👁️
Access

Request a copy of the personal data we hold about you.

✏️
Correction

Request correction of inaccurate or incomplete data.

🗑️
Deletion

Request deletion via our Delete Account page.

📦
Portability

Request an export of your data in a machine-readable format.

🚫
Opt-out

Unsubscribe from marketing emails at any time via the unsubscribe link.

⚙️
Restriction

Request that we restrict processing of your data in certain circumstances.

To exercise any of these rights, email us at contact@raftercore.com. We will respond within 30 days.

8. Cookies & Tracking

RafterCore uses browser localStorage (not traditional cookies) to store your session data, preferences, and cached business data for offline use. We do not use:

If we add analytics tools in the future, we will update this policy and notify users accordingly.

9. Children's Privacy

RafterCore is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us at contact@raftercore.com and we will promptly delete it.

10. Third-Party Services

Our platform links to and integrates with third-party services. When you use these integrations, you are also subject to those parties' privacy policies. We recommend reviewing the privacy policies of:

Lawful Basis for Processing (GDPR)

Where GDPR applies, RafterCore processes personal data under one or more of the following lawful bases:

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, RafterCore will:

To report a suspected breach or vulnerability, contact contact@raftercore.com with "Security" in the subject line.

11. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

To submit a CCPA request, email contact@raftercore.com with "CCPA Request" in the subject line.

12. International Users

RafterCore is operated in the United States. If you access the platform from outside the US, your data will be transferred to and processed in the US. By using RafterCore, you consent to this transfer. We ensure appropriate safeguards are in place for any international data transfers.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

The "Last updated" date at the top of this page reflects the most recent revision. Continued use of RafterCore after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

For privacy-related inquiries, data requests, or concerns:

RafterCore / RafterCore LLC

Email: contact@raftercore.com

Phone: 1-833-723-8371

Response time: within 30 days for data requests, within 5 business days for general inquiries.

12. GDPR — EU & UK Resident Rights

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:

International Data Transfers

RafterCore is operated from the United States. If you access our platform from the EU, EEA, or UK, your data will be transferred to and processed in the US. We rely on the following safeguards for international transfers:

Data Protection Officer

RafterCore does not currently meet the threshold requiring a formal DPO appointment. Privacy inquiries are handled by our founding team. Contact: contact@raftercore.com — Subject: "GDPR Request".

Supervisory Authority

You have the right to lodge a complaint with your local supervisory authority. EU residents may contact their national data protection authority. UK residents may contact the ICO (ico.org.uk).

To exercise any GDPR right, email contact@raftercore.com with "GDPR Request" in the subject line. We will respond within 30 days.